Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 11-03-2015 Ran by chris at 2015-03-13 21:18:50 Run:1 Running from C:\Users\chris\Desktop Loaded Profiles: chris & boinc_master & (Available profiles: chris & boinc_master) Boot Mode: Normal ============================================== Content of fixlist: ***************** CreateRestorePoint: ProxyEnable: [S-1-5-21-1161005709-739677458-2447788345-1001] => Internet Explorer proxy is enabled. ProxyServer: [S-1-5-21-1161005709-739677458-2447788345-1001] => http=127.0.0.1:9881 URLSearchHook: [S-1-5-21-1161005709-739677458-2447788345-1004] ATTENTION ==> Default URLSearchHook is missing. SearchScopes: HKU\S-1-5-21-1161005709-739677458-2447788345-1001 -> DefaultScope {015DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = http://taplika.com/r...=1612115114&ir= SearchScopes: HKU\S-1-5-21-1161005709-739677458-2447788345-1001 -> {015DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = http://taplika.com/r...=1612115114&ir= BHO: No Name -> {02478D38-C3F9-4efb-9B51-7695ECA05670} -> No File BHO: ArcadeYum Addon -> {651CA263-4157-4AC5-B7C2-03A7C1C00457} -> C:\Users\chris\AppData\Local\ArcadeYum\ArcadeYumIEHelper.dll [2014-10-31] () FF SelectedSearchEngine: Trovi CHR HomePage: Default -> hxxp://taplika.com/?f=1&a=tpl_tuto12_15_11&cd=2XzuyEtN2Y1L1QzuyEtDyCtCzzyCyCtDtB0F0Ezz0AyEyCyDtN0D0Tzu0StCtCyCyCtN1L2XzutAtFzztFtAtFtAtN1L1CzutN1L1G1B1V1N2Y1L1Qzu2StB0EyByBzyyBzytAtG0D0EtA0BtGtAyDzz0AtG0C0CtCyDtGtAyC0AtAyB0C0AtC0AyDtDzy2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0FyC0AyCyCtCyE0BtGtA0C0FtCtGyEtByE0AtG0A0F0CtCtG0FyBzyyEzyyCyE0FtB0CtAtC2QtN1B2Z1V1T1S1NzuyDzytA&cr=1612115114&ir= CHR StartupUrls: Default -> "hxxp://taplika.com/?f=7&a=tpl_tuto12_15_11&cd=2XzuyEtN2Y1L1QzuyEtDyCtCzzyCyCtDtB0F0Ezz0AyEyCyDtN0D0Tzu0StCtCyCyCtN1L2XzutAtFzztFtAtFtAtN1L1CzutN1L1G1B1V1N2Y1L1Qzu2StB0EyByBzyyBzytAtG0D0EtA0BtGtAyDzz0AtG0C0CtCyDtGtAyC0AtAyB0C0AtC0AyDtDzy2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0FyC0AyCyCtCyE0BtGtA0C0FtCtGyEtByE0AtG0A0F0CtCtG0FyBzyyEzyyCyE0FtB0CtAtC2QtN1B2Z1V1T1S1NzuyDzytA&cr=1612115114&ir=","hxxp://www.trovi.com/?gd=&ctid=CT3327155&octid=EB_ORIGINAL_CTID&ISID=MECB21F45-B317-49A7-962D-782A249956A4&SearchSource=55&CUI=&UM=8&UP=SP879BC58A-DCA3-4B35-B876-0472ABCE0400&D=031215&SSPV=" CHR DefaultSearchKeyword: Default -> Taplika.com CHR DefaultSearchURL: Default -> http://taplika.com/r...=1612115114&ir= CHR Extension: (Consumer Input) - C:\Users\chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc [2015-01-01] R2 CouponPrinterService; C:\Program Files\Coupons\CouponPrinterService.exe [153072 2014-09-05] (Coupons.com Inc.) R2 Mpidentantolycodal; C:\Program Files\Mpidentantolycodal\Mpidentantolycodal.exe [279040 2015-02-25] () [File not signed] <==== ATTENTION 2015-03-12 19:35 - 2015-03-12 19:35 - 00000000 ____D () C:\Users\chris\Documents\Optimizer Pro 2015-03-12 13:15 - 2015-03-12 13:18 - 00000000 __SHD () C:\Program Files\Mpidentantolycodal 2015-03-12 12:53 - 2015-03-12 22:07 - 00000000 ____D () C:\Program Files\globalUpdate 2015-03-12 12:53 - 2015-03-12 12:53 - 00000000 ____D () C:\Users\chris\AppData\Local\globalUpdate 2015-03-11 03:01 - 2015-02-06 19:09 - 00396419 _____ () C:\Windows\system32\ApnDatabase.xml 2015-03-12 22:16 - 2014-10-31 19:14 - 00000454 _____ () C:\Windows\Tasks\ArcadeYum.job Task: {439BBDA7-5710-42E8-A828-1C25E837EBFB} - System32\Tasks\ObronaCleanerUacSkip => C:\Users\chris\AppData\Local\Obrona Cleaner\ObronaCleaner.exe Task: {5BAADFC0-468B-4A1E-A7F4-24582289EBE9} - \Startup Time Check No Task File <==== ATTENTION Task: {669D0308-3172-4F5A-AED0-7F9BDF428FD4} - System32\Tasks\{337CFE7E-C41E-42EF-BB25-38B032B19C7A} => pcalua.exe -a "C:\Program Files\RelevantKnowledge\rlvknlg.exe" -c -bootremove -uninst:RelevantKnowledge Task: {86D82E91-6D13-4ED3-82BA-3BCD70CDB677} - \Run_Bobby_Browser No Task File <==== ATTENTION Task: {A3205BBF-8FC0-4917-95F2-16A68BA04EA6} - System32\Tasks\ArcadeYum => C:\Users\chris\AppData\Local\ArcadeYum\ArcadeYumVersionControl.exe Task: {FFEC7CB4-B86C-406D-ABFD-9BBD1AEE31D6} - \avayvaxxvae No Task File <==== ATTENTION Task: C:\Windows\Tasks\ArcadeYum.job => C:\Users\chris\AppData\Local\ArcadeYum\ArcadeYumVersionControl.exe C:\Users\chris\AppData\Local\ArcadeYum C:\Program Files\RelevantKnowledge RemoveProxy: EmptyTemp: CMD: bitsadmin /reset /allusers ***************** Restore point was successfully created. HKU\S-1-5-21-1161005709-739677458-2447788345-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable => value deleted successfully. HKU\S-1-5-21-1161005709-739677458-2447788345-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer => value deleted successfully. Error setting Default URLSearchHook. HKU\S-1-5-21-1161005709-739677458-2447788345-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully. "HKU\S-1-5-21-1161005709-739677458-2447788345-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{015DB5FA-EAFB-4592-A95B-F44D3EE87FA9}" => Key deleted successfully. HKCR\CLSID\{015DB5FA-EAFB-4592-A95B-F44D3EE87FA9} => Key not found. "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}" => Key deleted successfully. HKCR\CLSID\{02478D38-C3F9-4efb-9B51-7695ECA05670} => Key not found. "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{651CA263-4157-4AC5-B7C2-03A7C1C00457}" => Key deleted successfully. "HKCR\CLSID\{651CA263-4157-4AC5-B7C2-03A7C1C00457}" => Key deleted successfully. Firefox SelectedSearchEngine deleted successfully. Chrome HomePage deleted successfully. Chrome StartupUrls deleted successfully. Chrome DefaultSearchKeyword deleted successfully. Chrome DefaultSearchURL deleted successfully. C:\Users\chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc => Moved successfully. CouponPrinterService => Service stopped successfully. CouponPrinterService => Service deleted successfully. Mpidentantolycodal => Unable to stop service Mpidentantolycodal => Service deleted successfully. C:\Users\chris\Documents\Optimizer Pro => Moved successfully. C:\Program Files\Mpidentantolycodal => Moved successfully. C:\Program Files\globalUpdate => Moved successfully. C:\Users\chris\AppData\Local\globalUpdate => Moved successfully. C:\Windows\system32\ApnDatabase.xml => Moved successfully. C:\Windows\Tasks\ArcadeYum.job => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{439BBDA7-5710-42E8-A828-1C25E837EBFB}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{439BBDA7-5710-42E8-A828-1C25E837EBFB}" => Key deleted successfully. C:\Windows\System32\Tasks\ObronaCleanerUacSkip => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ObronaCleanerUacSkip" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{5BAADFC0-468B-4A1E-A7F4-24582289EBE9}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5BAADFC0-468B-4A1E-A7F4-24582289EBE9}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Startup Time Check" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{669D0308-3172-4F5A-AED0-7F9BDF428FD4}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{669D0308-3172-4F5A-AED0-7F9BDF428FD4}" => Key deleted successfully. C:\Windows\System32\Tasks\{337CFE7E-C41E-42EF-BB25-38B032B19C7A} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{337CFE7E-C41E-42EF-BB25-38B032B19C7A}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{86D82E91-6D13-4ED3-82BA-3BCD70CDB677}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{86D82E91-6D13-4ED3-82BA-3BCD70CDB677}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Run_Bobby_Browser" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A3205BBF-8FC0-4917-95F2-16A68BA04EA6}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A3205BBF-8FC0-4917-95F2-16A68BA04EA6}" => Key deleted successfully. C:\Windows\System32\Tasks\ArcadeYum => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ArcadeYum" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{FFEC7CB4-B86C-406D-ABFD-9BBD1AEE31D6}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FFEC7CB4-B86C-406D-ABFD-9BBD1AEE31D6}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\avayvaxxvae" => Key deleted successfully. C:\Windows\Tasks\ArcadeYum.job not found. C:\Users\chris\AppData\Local\ArcadeYum => Moved successfully. "C:\Program Files\RelevantKnowledge" => File/Directory not found. ========= RemoveProxy: ========= HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value deleted successfully. HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value deleted successfully. HKU\S-1-5-21-1161005709-739677458-2447788345-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value deleted successfully. HKU\S-1-5-21-1161005709-739677458-2447788345-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value deleted successfully. HKU\S-1-5-21-1161005709-739677458-2447788345-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable => value deleted successfully. HKU\S-1-5-21-1161005709-739677458-2447788345-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer => value deleted successfully. HKU\S-1-5-21-1161005709-739677458-2447788345-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value deleted successfully. HKU\S-1-5-21-1161005709-739677458-2447788345-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value deleted successfully. ========= End of RemoveProxy: ========= ========= bitsadmin /reset /allusers ========= BITSADMIN version 3.0 [ 7.7.9600 ] BITS administration utility. (C) Copyright 2000-2006 Microsoft Corp. BITSAdmin is deprecated and is not guaranteed to be available in future versions of Windows. Administrative tools for the BITS service are now provided by BITS PowerShell cmdlets. {EAD4EF3A-4A7B-487D-A1A5-43449C6CB2C9} canceled. 1 out of 1 jobs canceled. ========= End of CMD: ========= EmptyTemp: => Removed 265.7 MB temporary data. The system needed a reboot. ==== End of Fixlog 21:21:33 ====